CVE-2017-8787 PUBLISHED

The PoDoFo::PdfXRefStreamParserObject::ReadXRefStreamEntry function in base/PdfXRefStreamParserObject.cpp:224 in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted PDF file.

EPSS 0.45% · 63.6th percentile

Risk Scores

EPSS Score
0.45%
63.6th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSlibpodofo0, 0.9.0-1.1ubuntu1, 0.9.0-1.2
Ubuntu:Pro:16.04:LTSlibpodofo0, 0.9.0-1.3, 0.9.3-3

Timeline

References

Open in Interactive Console →